Skip to main content

Aspect Tech Knowledge IES

Cyber Resilience Act Reporting Obligations: What the 24-Hour Rule Means for Your Business (2026 Guide)

If your company has been treating the EU Cyber Resilience Act as a “2027 problem,” the calendar says otherwise. The CRA’s vulnerability and incident reporting obligations under Article 14 are already applicable from 11 September 2026. The remaining requirements, including essential cybersecurity requirements and CE marking, apply from 11 December 2027. If you build software, firmware, connected devices, or digital components that are available on the EU market, the reporting clock is already running. The key deadlines are an early warning within 24 hours, a fuller notification within 72 hours, and a final report within 14 days for actively exploited vulnerabilities. At Aspect, we put it simply: compliance is the lock, and security is the key. You need both.

01. The CRA is not one deadline—it is phased

The Cyber Resilience Act is being introduced in stages. The reporting obligation arrived well before the majority of the Act becomes applicable.
Date What it means for you
10 December 2024 The Cyber Resilience Act, formally Regulation (EU) 2024/2847, enters into force.
11 June 2026 Rules concerning conformity assessment bodies begin to apply.
11 September 2026 Article 14 reporting obligations become applicable. Manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security.
11 December 2027 The remaining CRA obligations become applicable, including essential cybersecurity requirements and CE marking.
A word of caution: December 2027 is not the first CRA deadline. If your product is already available on the EU market, your vulnerability and incident reporting process should already be operational.

02. Who must report under the CRA?

The reporting duty primarily sits with the manufacturer—an organisation that develops or manufactures a product with digital elements, or has one made, and markets it under its own name or trademark. In practice, this can include:
  • Software vendors selling on-premise, desktop, mobile, or embedded software in the EU.
  • Hardware and IoT manufacturers, including consumer smart devices and industrial equipment.
  • Component vendors when a component is placed on the EU market independently.
  • Importers and distributors that sell a product under their own brand or substantially modify it.
  • Non-EU companies whose products with digital elements are available on the EU market.
The location of your headquarters does not automatically remove the obligation. For Indian companies exporting software, firmware, IoT products, or other digital products to Europe, the CRA can therefore become directly relevant.

Is SaaS covered?

Pure software-as-a-service is generally outside the CRA where it falls under other EU cybersecurity regimes. However, cloud functionality that is essential to the core function of an installed product can potentially fall within scope. SaaS and cloud providers should therefore assess their products on a case-by-case basis rather than assuming that every cloud service is automatically exempt.

03. What actually triggers a CRA report?

Not every vulnerability or security update is automatically reportable. Article 14 focuses on two specific situations:
  • Actively exploited vulnerability: there is reliable evidence that a malicious actor has exploited a vulnerability in the product.
  • Severe incident: a cybersecurity incident affects the development, production, or maintenance processes of a product in a way that could increase risk for users.
A vulnerability discovered during internal testing or security research does not by itself trigger mandatory reporting if there is no evidence that it is being maliciously exploited. The European Commission has also clarified that third-party component vulnerabilities can require reporting where the vulnerability is exploitable and has been exploited in the manufacturer’s own product. Affected users must also be informed where required. In certain circumstances, the relevant national CSIRT may communicate with affected users directly.

04. The CRA reporting clock: 24 hours, 72 hours, 14 days

The biggest operational change for affected manufacturers is the speed at which they must respond after becoming aware of a qualifying event.
Stage Actively Exploited Vulnerability Severe Incident
Early warning Within 24 hours of becoming aware. Within 24 hours, including whether malicious or unlawful activity is suspected.
Notification Within 72 hours, including product details, the nature of the exploit, and corrective or mitigating measures. Within 72 hours, including product details, the nature of the incident, initial assessment, and mitigations.
Final report Within 14 days after a fix or mitigation becomes available. Within one month of the notification.
The 24-hour clock starts when the manufacturer becomes aware of the qualifying event after an initial assessment provides a reasonable degree of certainty that the product is being exploited or its security has been compromised. This makes fast detection, triage, escalation, and incident ownership critical.

05. Where do CRA reports go?

CRA reports are submitted through ENISA’s CRA Single Reporting Platform (SRP). The platform routes the report to the relevant CSIRT coordinator and other appropriate member-state authorities. This means manufacturers should not rely on simply emailing a national CSIRT as a substitute for the required reporting process. Your organisation should have:
  • A designated person responsible for CRA reporting.
  • A backup person who can submit reports when the primary contact is unavailable.
  • EU Login access with appropriate authentication.
  • Accurate legal entity and product information.
  • A documented escalation process for incidents discovered outside business hours.

06. CRA reporting and other cyber regulations

One cybersecurity incident can potentially trigger obligations under multiple regulatory frameworks. For an Indian company selling products or services into Europe, the same event may involve CRA reporting alongside CERT-In, GDPR, NIS2, or India’s DPDP requirements. A CRA notification does not automatically satisfy the obligations of these other regimes.
Regime Who it applies to First deadline
CERT-In Directions Organisations operating in India for specified cyber incidents 6 hours
EU Cyber Resilience Act Manufacturers of products with digital elements on the EU market 24 hours
NIS2 Directive Essential and important entities in the EU 24 hours
GDPR Controllers processing EU personal data 72 hours
DPDP Act and Rules Data fiduciaries processing digital personal data in India Without delay / detailed report within 72 hours
The practical approach is to maintain one integrated incident response playbook that identifies every regulatory obligation when an incident is detected.

07. What are the penalties for missing a CRA report?

The CRA uses a three-tier fine structure. Breaches involving essential requirements and core manufacturer obligations, including Article 14 reporting, sit within the highest tier.
Type of breach Maximum fine
Essential requirements and core manufacturer obligations €15 million or 2.5% of worldwide annual turnover, whichever is higher.
Other obligations, including certain importer and distributor duties €10 million or 2% of worldwide annual turnover.
Incorrect, incomplete, or misleading information €5 million or 1% of worldwide annual turnover.
Market surveillance authorities can also require documentation, demand corrective action, or order products to be withdrawn or recalled from the EU market.

08. Your 7-step CRA reporting readiness plan

Step 1: Inventory your products

  • List every product with digital elements available in the EU.
  • Include legacy products and supported versions.
  • Document third-party components and dependencies.
  • Identify products that are white-labelled or sold under another company’s brand.

Step 2: Confirm who the manufacturer is

  • Identify the legal entity responsible for each product.
  • Review arrangements involving IP owners, development companies, distributors, and white-label partners.
  • Document which organisation holds the manufacturer role.

Step 3: Identify your CSIRT coordinator

  • Determine the relevant EU establishment and CSIRT coordination route.
  • If you have no EU establishment, map the applicable route through your authorised representative, importer, or relevant EU presence.

Step 4: Prepare access to the Single Reporting Platform

  • Set up the necessary EU Login accounts.
  • Use multi-factor authentication.
  • Assign a primary and backup reporting representative.
  • Standardise legal entity and product information.

Step 5: Define your incident triage process

  • Define what constitutes active exploitation.
  • Define what constitutes a severe incident.
  • Identify who makes the reporting decision.
  • Create an escalation path for incidents discovered outside working hours.
  • Ensure the organisation can act within the 24-hour reporting window.

Step 6: Pre-draft your notifications

  • Create an early-warning template.
  • Prepare the 72-hour notification template.
  • Prepare final-report documentation.
  • Create customer advisory templates.

Step 7: Map and rehearse your regulatory obligations

  • Map CRA requirements against CERT-In, GDPR, NIS2, and DPDP obligations.
  • Run a tabletop incident-response exercise.
  • Test the process from initial detection through regulatory filing.

09. Common CRA reporting mistakes

  • Treating December 2027 as the first CRA deadline.
  • Assuming all SaaS and cloud components are automatically outside the CRA.
  • Emailing a national CSIRT instead of using the Single Reporting Platform.
  • Forgetting white-label and OEM products.
  • Leaving reporting access with only one employee.
  • Failing to maintain a 24/7 escalation process.
  • Not rehearsing the reporting process before an actual incident occurs.

10. How Aspect Tech Knowledge IES can help

At Aspect Tech Knowledge IES, we believe compliance is the lock and security is the key. Our team helps product companies translate regulations such as the Cyber Resilience Act into practical and repeatable security processes—from product scoping and CSIRT mapping to incident-response playbooks aligned with CERT-In, GDPR, NIS2, and DPDP requirements. If you want to understand whether your products fall within the CRA and whether your team could meet a 24-hour reporting deadline, speak with our team about a CRA reporting readiness review. Talk to us at connect@aspect-tech-knowledge-ies.com .

11. Frequently asked questions

When did the Cyber Resilience Act reporting obligations start?

The CRA reporting obligations under Article 14 started on 11 September 2026. Most other CRA requirements, including essential cybersecurity requirements and CE marking, apply from 11 December 2027.

What is the 24-hour rule under the CRA?

Manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident affecting their product. A fuller notification follows within 72 hours.

Does the CRA apply to companies outside the EU?

Yes. The CRA applies to manufacturers whose products with digital elements are available on the EU market, regardless of where the company is headquartered. This can include Indian, US, and other non-EU manufacturers.

Where are CRA reports submitted?

Reports are submitted through ENISA’s CRA Single Reporting Platform, which routes the information to the relevant CSIRT coordinator.

Do products sold before September 2026 need to be considered?

Yes. The reporting obligations apply to in-scope products already available on the EU market, including products placed on the market before 11 September 2026.

What is the maximum CRA penalty?

For breaches involving essential requirements and core manufacturer obligations, fines can reach €15 million or 2.5% of worldwide annual turnover, whichever is higher.

What happens if a company misses a CRA reporting deadline?

In addition to financial penalties, market surveillance authorities can require corrective action and may order products to be withdrawn or recalled from the EU market.

12. Start preparing before the 24-hour clock starts

The organisations that can respond calmly to CRA reporting obligations are the ones that prepare before an incident occurs. Product inventories, incident ownership, vulnerability monitoring, reporting access, pre-drafted notifications, and rehearsed response procedures all take time to establish. The 24-hour reporting window is too short to build the process after an incident has already been detected. Aspect Tech Knowledge IES helps organisations understand their CRA exposure and build the security and incident-response foundation needed to respond quickly. Talk to us at connect@aspect-tech-knowledge-ies.com . Deeper Understanding. Better Solutions.

Sources

This article is for general information and is not legal advice. Please confirm your specific obligations with qualified advisers.